VYPR

Vendor CVEs

Janobe

All CVEs

196 total · sorted by risk
  • CVE-2025-10596HigSep 17, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument usn results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…

  • CVE-2025-10482HigSep 15, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now…

  • CVE-2025-10479HigSep 15, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely.…

  • CVE-2025-9706HigAug 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester Water Billing System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit…

  • CVE-2025-9705HigAug 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to…

  • CVE-2025-9704HigAug 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the…

  • CVE-2025-9700HigAug 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published…

  • CVE-2025-9660HigAug 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out…

  • CVE-2024-48245HigJan 7, 2025
    risk 0.47cvss 7.2epss 0.01

    Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment…

  • CVE-2024-0182HigJan 1, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ of the component Admin Login. The manipulation of the argument username/password leads to sql injection.…

  • CVE-2022-38576HigSep 19, 2022
    risk 0.47cvss 7.2epss 0.01

    Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=.

  • CVE-2022-38833HigSep 16, 2022
    risk 0.47cvss 7.2epss 0.01

    School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.

  • CVE-2022-38832HigSep 16, 2022
    risk 0.47cvss 7.2epss 0.01

    School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.

  • CVE-2022-38269HigSep 8, 2022
    risk 0.47cvss 7.2epss 0.01

    School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=.

  • CVE-2022-38268HigSep 8, 2022
    risk 0.47cvss 7.2epss 0.01

    School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=.

  • CVE-2022-38267HigSep 8, 2022
    risk 0.47cvss 7.2epss 0.01

    School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=.

  • CVE-2022-38260HigSep 8, 2022
    risk 0.47cvss 7.2epss 0.01

    Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=questiondelete&id=.

  • CVE-2022-38255HigSep 8, 2022
    risk 0.47cvss 7.2epss 0.01

    Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /interview/editQuestion.php.

  • CVE-2021-40578HigDec 7, 2021
    risk 0.47cvss 7.2epss 0.01

    Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.

  • CVE-2021-25780HigFeb 17, 2021
    risk 0.47cvss 7.2epss 0.03

    An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.

  • CVE-2024-33994HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.

  • CVE-2024-33993HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.

  • CVE-2024-33992HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in…

  • CVE-2024-33991HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in…

  • CVE-2024-33990HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id'…

  • CVE-2024-33989HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via…

  • CVE-2024-33988HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33987HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33986HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter…

  • CVE-2024-33985HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter…

  • CVE-2024-33984HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33983HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33982HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID'…

  • CVE-2024-33981HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in…

  • CVE-2024-33980HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in…

  • CVE-2024-33979HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and…

  • CVE-2024-33978HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.

  • CVE-2024-33977HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.

  • CVE-2024-33976HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in…

  • CVE-2024-33975HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'view' parameter in…

  • CVE-2026-3800MedMar 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit…

  • CVE-2026-3771MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2025-13236MedNov 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is…

  • CVE-2025-13234MedNov 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID results in sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-12939MedNov 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched…

  • CVE-2025-12933MedNov 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid leads to sql injection. The attack can be launched remotely. The exploit is…

  • CVE-2025-12931MedNov 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-12930MedNov 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…

  • CVE-2025-12926MedNov 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made…

  • CVE-2025-11487MedOct 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing manipulation of the argument Type results in sql injection. The attack may be initiated remotely. The…